How the Downandup Worm works
  • 11 Comments
by John Biggs on January 20, 2009

windows_vista_open_folder_to_view_files

This is pretty interesting: there’s a new worm called Downandup that basically uses social engineering to spread itself.

Take a look at that screenshot. Notice anything weird?

When you insert a USB drive, it usually says something like “Open folder to view files.” Fair enough. But notice that there is a program that says the same thing “published by Microsoft.” That’s the trick. It basically convinces you that its a system action when it’s really an application. Tricksy tricksy.

Comments rss icon

Leave Comment

Commenting Options

Enter your personal information to the left, or sign in with your Facebook account by clicking the button below.

Alternatively, you can create an avatar that will appear whenever you leave a comment on a Gravatar-enabled blog.

Trackback URL
bugbugbug